CVE-2026-26056Disclosure(yokecd / yoke)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR create/update permissions to execute arbitrary WASM code in the ATC controller context by injecting a malicious URL through the overrides.yoke.cd/flight annotation. The ATC controller downloads and executes the WASM module without proper URL validation, enabling attackers to create arbitrary Kubernetes resources or potentially escalate privileges to cluster-admin level.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • yoke

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-13)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
yoke

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 1Mentions · 2026-02-13: 2Technical Details · 2026-02-13: 202-1202-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-02-132
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-26056 Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of … https://www.cve.org/CVERecord?id=CVE-2026-26056

    Post summary

    The passage notes the existence of CVE-2026-26056 affecting Yoke’s Air Traffic Controller component, with no further technical details, exploitation evidence, or remediation information.

    00020231
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Arbitrary WASM code execution (CVE-2026-26056) impacts `yokecd/yoke` in its `Yoke ATC` component via AnnotationOverrideFlight injection. Organizations should review their deployments. #WASM #CodeExecution #infosec https://www.pulsepatch.io/posts/cve-2026-26056-yoke-wasm-code-execution

    Post summary

    The tweet announces CVE-2026-26056, a WASM code‑execution flaw in yokecd/yoke’s Yoke ATC component via AnnotationOverrideFlight injection, urging organizations to review their deployments.

    0000029
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26056: Yoke ATC: Flying Blind into WASM RCE A critical remote code execution vulnerability in Yoke's Air Traffic Controller (ATC) component allows attackers to execute arbitrary WebAssembly (WASM) modules via simple Kubernetes annotations. By... https://cvereports.com/reports/CVE-2026-26056

    Post summary

    A critical RCE vulnerability in Yoke’s ATC component permits attackers to run arbitrary WebAssembly modules through Kubernetes annotations.

    0000051
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyokecdyoke---

Explore more